
Create your own vulnerable by design AWS penetration testing playground

Start Hacking: CloudFoxable
Read the blog for more details: Introducing CloudFoxable: A Gamified Cloud Hacking Sandbox
CloudFox helps penetration testers and security professionals find exploitable attack paths in cloud infrastructure. However, what if you want to find and exploit services not yet present in your current environment? What if you lack access to an enterprise AWS environment?
Enter CloudFoxable, an intentionally vulnerable AWS environment created specifically to showcase CloudFox’s capabilities and help you find latent attack paths more effectively. Drawing inspiration from CloudGoat, flaws.cloud, flaws2.cloud and Metasploitable 1-3, CloudFoxable provides a wide array of flags and attack paths in a CTF format.
Similar to CloudGoat and IAM-Vulnerable, CloudFoxable deploys intentionally vulnerable AWS resources in a user-managed playground account, for users to learn about identifying and exploiting cloud vulnerabilities. However, more like flaws.cloud, your experience is more web based and guided.
CloudFoxable uses Terraform to deploy and manage intentionally vulnerable AWS infrastructure. This section provides the minimum required guidance to get Terraform installed and to deploy, modify, and remove CloudFoxable resources.
Terraform must be installed locally before deploying CloudFoxable.
Follow the official HashiCorp installation guide for your operating system:
https://developer.hashicorp.com/terraform/tutorials/aws-get-started/install-cli
Verify the installation:
terraform version
A successful install will print the Terraform version.
Before running Terraform:
aws configure, environment variables, or an assumed role).Important: CloudFoxable deploys intentionally vulnerable infrastructure. Do not deploy this in production, shared, or corporate AWS accounts.
All Terraform commands should be run from the following directory:
cd cloudfoxable/aws
Initialize the working directory and download required providers:
terraform init
This is required once per workspace (or when provider configuration changes).
To review what Terraform will create, modify, or destroy:
terraform plan
To deploy the currently enabled challenges:
terraform apply
Type yes when prompted to confirm.
To remove all CloudFoxable-created resources:
terraform destroy
Confirm with yes when prompted.
| Command | Description |
|---|---|
terraform init | Initialize the Terraform project |
terraform plan | Show proposed infrastructure changes |
Similar to IAM-Vulnerable, some challenges are enabled by default (the ones that have little or no cost implications), and others are disabled by default (the ones that incur cost if deployed). This way, you can enable specific modules as needed. The mechanism for enabling/disabling challenges is a little different than IAM-Vulnerable though.
Within cloudfoxable.bishopfox.com, each challenge will tell you if you need to make any terraform changes (aka deploy something) to complete the challenge. The way you do this is to edit terraform.tfvars and update the enabled flag from false to true as needed.
Here's an example:
############################
# Enabled/Disabled Challenges
############################
# Always on (Low or No cost)
challenge_foo_enabled = true
challenge_bar_enabled = true
challenge_alice_enabled = true
# Enable as needed (These challenges incur cost)
challenge_bob_enabled = false
challenge_mallory_enabled = false
To enable the mallory challenge, you would simply update the following line:
challenge_mallory_enabled = true
After you enable a challenge, you will need to re-run terraform apply:
terraform apply
You have now deployed the mallory challenge.
Cleanup
Whenever you want to remove all of the CloudFoxable-created resources, you can run these commands:
cd cloudfoxable/awsterraform destroyIf you're using Windows, you might encounter issues when deploying some of the challenges due to platform-specific limitations. To avoid this, a Dockerfile is provided to help you build and run the application in a consistent environment across different systems.
Start by cloning the repository to your local machine:
git clone https://github.com/BishopFox/cloudfoxable.git
cd cloudfoxable
Once you have cloned the repository, build the Docker image with the following command. This will ensure that you are using a fresh build without any cached layers:
docker build --no-cache -t cloudfoxable .
If you're on Windows, use the following PowerShell command to run the Docker container. This will:
cd aws
docker run -it -v $env:USERPROFILE/.aws/credentials:/root/.aws/credentials -v ${PWD}:/cloudfoxable/aws cloudfoxable
If you'd like to add a new challenge, here's the steps within CloudFoxable once you fork the repo:
cp aws/challenges/1_challenge_template aws/challenges/challenge_namechallenge_name.tf file to the name of your challenge.variable "challenge_name_enabled" {
description = "Enable or disable challenge_name challenge (true = enabled, false = disabled)"
type = bool
default = false
}
terraform.tfvars.example. Specify if it should be enabled by default (low/no cost), or disabled by default (costs $$)
challenge_name_enabled = false
module "challenge_challenge_name" {
source = "./challenges/challenge-name"
count = var.challenge_name_enabled ? 1 : 0
aws_assume_role_arn = (var.aws_assume_role_arn != "" ? var.aws_assume_role_arn : data.aws_caller_identity.current.arn)
account_id = data.aws_caller_identity.current.account_id
aws_local_profile = var.aws_local_profile
user_ip = local.user_ip
}
enabled_challenges local variable:
var.challenge_name_enabled ? "name | $12/month |" : ""
terraform apply | Create or update resources |
terraform destroy | Remove all deployed resources |